Impact
The vulnerability arises in the Linux kernel’s libsas component, where a deadlock is triggered during high‑availability resume operations and a race condition can cause SAS disks to be disabled while they are still waking. The deadlock occurs when the HA resume handler waits for the host to become active, while the host simultaneously waits for the handler to finish, leading to a system hang. The race allows an autosuspending controller to interrupt disks that are still in the process of waking, resulting in failed I/O and disk disablement, which effectively denies service to affected storage devices.
Affected Systems
The impacted systems are Linux kernel installations that include libsas and its consumer drivers such as hisi_sas, isci, pm8001, aic94xx, and mvsas. All kernel versions that contain this vulnerable libsas implementation are potentially affected; however, specific affected version ranges are not listed in the available data.
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity if the conditions are met. The EPSS score is less than 1 %, showing a very low likelihood that this issue will be actively exploited by attackers at this time. Because the vulnerability is not listed in the CISA KEV catalog, no known, widely‑available exploits exist. Exploitation would likely require privileged access to trigger suspend/resume cycles or manipulate the runtime power management of the SAS controllers, so the overall risk remains moderate in severity but low in practical exploitation probability.
OpenCVE Enrichment
Debian DSA